Federal PQC Mandates: EO 14412, OMB M-26-15, and CNSA 2.0
What EO 14412 and OMB M-26-15 require, how they fit with CNSA 2.0 and M-23-02, federal PQC migration deadlines, and what agencies and contractors should do now.
Federal post-quantum migration now has hard dates. Executive Order 14412 and OMB Memorandum M-26-15 turned a four-year trajectory of guidance into a deadline-driven program, and the first obligation, an agency migration plan, has a 120-day clock. Agencies and contractors that treated PQC as a future research topic are now working against a schedule.
The federal PQC mandate stack, in order
The June 2026 instruments did not appear from nowhere. They build on a sequence of policy, statute, and standards that each added a piece.
- NSM-10 (White House, May 2022) set the national goal: begin migrating vulnerable systems and mitigate as much quantum risk as feasible by 2035.
- CNSA 2.0 (NSA, September 2022) defined the algorithm suite for national security systems (NSS): ML-KEM-1024 for key establishment, ML-DSA-87 for signatures, LMS or XMSS for software and firmware signing, AES-256, and SHA-384 or SHA-512.
- OMB M-23-02 (November 2022) required annual cryptographic inventories, with priority on high-impact systems and long-lived data.
- The Quantum Computing Cybersecurity Preparedness Act (Public Law 117-260, December 2022) made inventory, migration planning, and progress reporting a statutory obligation.
- FIPS 203, 204, and 205 (NIST, August 2024) finalized ML-KEM, ML-DSA, and SLH-DSA.
- NIST IR 8547 (draft, November 2024) proposed deprecating RSA and ECC after 2030 and disallowing them after 2035.
- EO 14306 (June 2025) directed CISA to publish a list of product categories where PQC-capable products are widely available (released January 2026) and required TLS 1.3 support by January 2030.
What EO 14412 requires
Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (June 2026), converts the direction above into firm obligations:
- Every agency designates a PQC migration lead.
- Key establishment moves to NIST-approved post-quantum cryptography by December 31, 2030.
- Digital signatures move by December 31, 2031.
- A FAR rule is directed that will require covered contractors to meet NIST PQC standards by the end of 2030.
The sequencing is deliberate. Key establishment comes first because of harvest now, decrypt later: traffic recorded today under RSA or ECDH key exchange can be decrypted once a capable quantum computer exists. Signatures require a quantum attack at the time of use, so they follow a year later. The 2030 key establishment date also hardens the deprecation point that NIST IR 8547 had only proposed.
What OMB M-26-15 requires
OMB M-26-15, Execution of the Migration to Post-Quantum Cryptography (June 2026) is the execution roadmap for the order. It requires agency migration plans within 120 days, sets a phased migration from 2026 through 2035 that prioritizes High Value Assets and High Impact Systems, and aligns the work with FIPS 203, 204, and 205.
In practice, the migration plan is where the M-23-02 inventory stops being a reporting artifact and becomes the basis for sequencing, budgeting, and accountability.
Federal PQC migration deadlines and CNSA 2.0 timeline
| Date | Requirement | Source | Applies to |
|---|---|---|---|
| Annually | Cryptographic inventory, prioritizing high-impact systems and long-lived data | OMB M-23-02 | Federal agencies |
| 120 days from M-26-15 (June 2026) | Agency PQC migration plan | OMB M-26-15 | Federal agencies |
| January 1, 2027 | New NSS acquisitions must support CNSA 2.0 | CNSA 2.0 | National security systems |
| January 2030 | TLS 1.3 support | EO 14306 | Federal agencies |
| End of 2030 | Equipment that cannot support CNSA 2.0 phased out | CNSA 2.0 | National security systems |
| End of 2030 | Covered contractors meet NIST PQC standards (via forthcoming FAR rule) | EO 14412 | Federal contractors |
| December 31, 2030 | Key establishment on NIST-approved PQC | EO 14412 | Federal agencies |
| December 31, 2031 | Digital signatures on NIST-approved PQC | EO 14412 | Federal agencies |
| 2033 | NSS transition to CNSA 2.0 complete | CNSA 2.0 | National security systems |
| 2035 | Quantum risk mitigated as far as feasible; RSA and ECC disallowed (proposed) | NSM-10, NIST IR 8547 (draft) | Federal systems |
Two details are easy to miss. First, the CNSA 2.0 acquisition date of January 1, 2027 is closer than any EO 14412 deadline, so NSS program offices are buying against it now. Second, CNSA 2.0 specifies ML-KEM-1024 and ML-DSA-87. The hybrid X25519 + ML-KEM-768 default common in commercial TLS stacks is a sound step for civilian systems, but it does not by itself meet the NSS parameter requirements.
PQC requirements for federal contractors
The FAR rule directed by EO 14412 has not been finalized, and its clause text and scope are not yet known. The end-of-2030 target is known. For contractors, waiting for the clause is the expensive option: product roadmaps, HSM and firmware refresh cycles, and certificate hierarchies take years to change.
What contractors can do now:
- Build your own cryptographic inventory for the products and services you deliver to government, including third-party libraries and embedded components.
- Map your products against CNSA 2.0 if you sell into national security systems, since the 2027 acquisition requirement already applies.
- Check the CISA PQC product category list released under EO 14306 and know where your products sit relative to it.
- Prepare to answer customer questions with evidence: which algorithms, where, and what the migration path is. Agencies writing migration plans will ask their suppliers.
- Plan TLS 1.3 support everywhere, since hybrid and post-quantum key exchange depend on it.
The first 120 days: a practical sequence for agencies
The 120-day plan is the first concrete deliverable. A workable sequence:
- Designate the PQC migration lead and give the role authority across CIO, CISO, acquisition, and program offices. Cryptography crosses all of them.
- Start from the M-23-02 inventory, then close its gaps. Annual inventories often capture algorithms and certificates but miss libraries, configuration-selected algorithms, HSM firmware, and vendor-managed components.
- Identify High Value Assets and High Impact Systems in the inventory, as M-26-15 directs, and flag which protect long-lived data.
- Separate key establishment from signatures in the plan, matching the 2030 and 2031 deadlines.
- Classify each item by migration path: configuration change, library upgrade, hardware or firmware refresh, or vendor dependency. Vendor dependencies need acquisition action early.
- Surface blockers: systems without TLS 1.3, HSMs without PQC support, constrained networks where larger handshakes and certificate chains will cause failures.
- Engage suppliers with specific questions about PQC support and timelines, and write PQC requirements into new acquisitions now.
- Define the evidence you will use to show progress, so that reporting reflects verified technical state rather than self-attestation.
How QuantumWorks approaches federal PQC migration
We work on this problem within our cyber assurance area. Sentinel builds a Crypto Asset Graph from code, protocol, infrastructure, and policy evidence, ties findings to mandate requirements, scores risk by mission impact and HNDL exposure, and produces a dependency-aware migration roadmap in POA&M form with a CycloneDX 1.6 CBOM anchored to evidence. CAM addresses the adjacent problem of keeping control and posture claims continuously verifiable against the technical evidence behind them. More on our work for federal missions is on our government page.